Help - Search - Members - Calendar
Full Version: PWSteal.Trojan
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
DayDreamBeliever
Hello all :)

Thanks to this forum, I was able to update NAV and get rid of the Gaobot virus by following the instructions in CalamityJane's thread "ATTN NAV USERS: R6025 error". Thank you so much for that Calamity :)

I have also downloaded & installed all the Windows patches available and sworn an oath to never postpone an update again!

I still have a virus problem. The NAV scan detected a file infected with the PWSteal.Trojan virus but was unable to either quarantine or delete the file. I tried following Symantec' solution to resolve that problem (which was a simple Search & Delete of the infected file) but the search found no result with the file name.

The infected file is in the Temporary Internet Files so I tried to use the temporary Internet files deleting function in IE and that failed too :( (the program was unresponding...)

If anyone has had a similar problem or knows how I could get rid of the virus, I would greatly appreciate your help!

Should I run an HIJACKTHIS scan for that kind of problem???

Thanks,

Day
CalamityJane
Hi DayDreamBeliever,

Am sooooo glad to hear that the instructions helped you with Gaobot :)

And am even more glad to hear you will be updating Windows more often (updates are usually released on the 2nd Tuesday of each month) :thumb:

Make sure your PC is configured to show hidden files
How to Show Hidden Files
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

Then restart your PC in SAFE MODE

How to start the computer in Safe mode
http://service1.symantec.com/SUPPORT/tsgen...src=sec_doc_nam

Scan with your NAV and it should be able to delete or quarantine the file.

While in Safe mode see if you can delete the contents of your TIF folder

If still no joy, reboot and download HijackThis and post a log. Perhaps we can see something there :)
DayDreamBeliever
Thank you Calamity!

My umpteenth scan in the last few of days says I'm clean ahah.gif Plus I was able to empty the TIF folder.

I've been spreading the good word about Window Update to my friends and at work ;)

I'm really glad I found this forum.

Thanks for the help again :)

Wave.gif
Day
CalamityJane
Bless you sweetheart, spread the news and help the others - we are all volunteers here to help the internet community :wub:
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.